漏洞描述
FRP default login credentials were discovered.
id: frp-default-login
info:
name: FRP Default Login
author: pikpikcu
severity: high
description: FRP default login credentials were discovered.
reference:
- https://github.com/fatedier/frp/issues/1840
classification:
cwe-id: CWE-798
metadata:
max-request: 1
tags: frp,default-login,vuln
http:
- raw:
- |
GET /api/proxy/tcp HTTP/1.1
Host: {{Hostname}}
Authorization: Basic {{base64(username + ':' + password)}}
payloads:
username:
- admin
password:
- admin
attack: pitchfork
matchers-condition: and
matchers:
- type: word
words:
- '"proxies":'
part: body
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100aabad20190aacd067db445b781de3f67d01a9fb75e8b7c2a3a7d4d5bdbb5436a022100fb21c078d6d9db5c822adea48db9f7188f4e505c677c805f2f8807328d5519b7:922c64590222798bb761d5b6d8e72950